#VU18252 Out-of-bounds read in libssh2 - CVE-2019-3861
Published: April 15, 2019 / Updated: April 15, 2019
libssh2
libssh2.org
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information or perform denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when SSH packets with a padding length value greater than the packet length are parsed. A remote attacker can trick the victim to connect to a malicious SSH server, trigger out of bounds read and gain access to sensitive information or perform denial of service attack.